CVE-2026-45207
Privilege Escalation in Apex One/SEP Agent
Publication date: 2026-05-21
Last updated on: 2026-05-21
Assigner: Trend Micro, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| trendmicro | apex_one | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-346 | The product does not properly verify that the source of data or communication is valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an origin validation flaw in the Apex One/SEP agent. It allows a local attacker, who already has the ability to run low-privileged code on the system, to escalate their privileges. The issue is related to the process protection communication mechanism and is similar to another vulnerability identified as CVE-2026-45206.
How can this vulnerability impact me? :
If exploited, this vulnerability can allow an attacker with limited access to gain higher privileges on the affected system. This means the attacker could potentially perform actions that require elevated permissions, compromising the security and integrity of the system.